76/100 SECURITY SCORE

Certificate Information

Subject
CN=createawebsite.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026 56 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0A:A9:9D:98:73:66:67:13:20:EA:CA:B8:2F:05:F3:68:4B:65:0C:55:9A:50:85:F5:A8:3F:87:45:5D:3F:68:9E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
createawebsite.it *.createawebsite.it *.admin.createawebsite.it *.analytics.createawebsite.it *.bi.createawebsite.it *.chart.createawebsite.it *.dashboards.createawebsite.it *.dev.createawebsite.it

Other domains in certificate

*.admin.approve.chat *.api.approve.chat *.app.approve.chat approve.chat *.approve.chat *.assets.approve.chat *.backup.approve.chat *.dashboard.approve.chat *.dev.approve.chat *.gcjxbstg.approve.chat *.gityduat.approve.chat *.oerhvkau.approve.chat *.portal.approve.chat *.public.approve.chat *.sharepoint.approve.chat *.v2.approve.chat
*.access.mbgmbh.com *.admin.mbgmbh.com *.amplitude.mbgmbh.com *.api.mbgmbh.com *.app.mbgmbh.com *.apps.mbgmbh.com *.assets.mbgmbh.com *.auth.mbgmbh.com *.b2b.mbgmbh.com *.backup.mbgmbh.com *.buildkite.mbgmbh.com *.canvas.mbgmbh.com *.citrix.mbgmbh.com *.cloud.mbgmbh.com *.comet.mbgmbh.com *.comms.mbgmbh.com *.community.mbgmbh.com *.crypto.mbgmbh.com *.demo.mbgmbh.com *.dev.mbgmbh.com *.drvpn.mbgmbh.com *.ebd896de-8a29-4d3d-a3c3-459067eed4eb.mbgmbh.com *.gateway.mbgmbh.com *.govvkm.mbgmbh.com *.kgabqmail.mbgmbh.com *.life.mbgmbh.com *.m.mbgmbh.com *.mail.mbgmbh.com mbgmbh.com *.mbgmbh.com *.navwiportal.mbgmbh.com *.portal.mbgmbh.com *.prelogon.mbgmbh.com *.rd.mbgmbh.com *.rdp.mbgmbh.com *.rds.mbgmbh.com *.rds1.mbgmbh.com *.rdweb.mbgmbh.com *.remote.mbgmbh.com *.remoto.mbgmbh.com *.secure.mbgmbh.com *.soa.mbgmbh.com *.sslvpn.mbgmbh.com *.staging.mbgmbh.com *.studentsvpn.mbgmbh.com *.teams.mbgmbh.com *.test.mbgmbh.com *.txleqbackup.mbgmbh.com *.uat.mbgmbh.com *.vpn.mbgmbh.com
*.0dc.njrypxs.cn *.bftybvxqddvbwmjgd.njrypxs.cn *.dzop8e1.njrypxs.cn *.gzbsr.njrypxs.cn *.hrpq.njrypxs.cn *.m.njrypxs.cn *.mzd.njrypxs.cn njrypxs.cn *.njrypxs.cn *.urj.njrypxs.cn *.wk.njrypxs.cn
*.dev.retreatselite.com *.news.retreatselite.com retreatselite.com *.retreatselite.com *.web.retreatselite.com